PT-2023-8787 · Veritas · Veritas Netbackup It Analytics

CVE-2023-28818

·

Publicado

2023-03-24

·

Atualizado

2023-03-31

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Veritas NetBackup IT Analytics versions prior to 11.2.0
Description The issue is related to errors in cryptographic signature verification, which could allow a remote attacker to compromise data integrity. A malicious actor could exploit the application upgrade process, which includes unsigned files, to install rogue Collector executable files, such as aptare.jar or upgrademanager.zip, on the Portal server. These files might then be downloaded and installed on collectors.
Recommendations For Veritas NetBackup IT Analytics versions prior to 11.2.0, update to version 11.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Portal server to minimize the risk of exploitation. Avoid using the unsigned files in the application upgrade process until the issue is resolved.

Correção

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-01905
CVE-2023-28818

Produtos afetados

Veritas Netbackup It Analytics